sweedworks

← all sources

checkcookies.py

What is actually in the browser's cookie store

68 lines. This is the file the build actually runs, copied verbatim at build time.

  1. 1"""Any cookie set while loading the site, read from Chrome's own cookie store.
  2. 2 
  3. 3Every page footer says "no cookies". checklive.py only ever checked for a
  4. 4Set-Cookie *header* — but a script can set one with document.cookie, and
  5. 5Cloudflare runs a fingerprinting script on every page here. So the claim was
  6. 6verified in the one place it was least likely to fail.
  7. 7 
  8. 8Run shot.sh against a page first (ideally after deleting the profile, so the
  9. 9store starts empty), then:
  10. 10 
  11. 11 python3 checkcookies.py
  12. 12"""
  13. 13 
  14. 14import os
  15. 15import sqlite3
  16. 16import sys
  17. 17 
  18. 18PROFILE = "/var/www/sweedworks/.chrome-home"
  19. 19STORE = os.path.join(PROFILE, "Default", "Cookies")
  20. 20 
  21. 21 
  22. 22def main():
  23. 23 if not os.path.exists(STORE):
  24. 24 print(f"no cookie store at {STORE}")
  25. 25 print("Chrome did not create one, which means nothing tried to set a "
  26. 26 "cookie.")
  27. 27 return 0
  28. 28 
  29. 29 # Copy first: the store may be locked, and we must not modify it.
  30. 30 tmp = "/tmp/claude-996/cookies-copy.sqlite"
  31. 31 with open(STORE, "rb") as src, open(tmp, "wb") as dst:
  32. 32 dst.write(src.read())
  33. 33 
  34. 34 con = sqlite3.connect(tmp)
  35. 35 try:
  36. 36 rows = con.execute(
  37. 37 "SELECT host_key, name, path, is_secure, is_httponly, "
  38. 38 "has_expires, is_persistent FROM cookies").fetchall()
  39. 39 except sqlite3.DatabaseError as e:
  40. 40 print(f"could not read cookie store: {e}")
  41. 41 return 1
  42. 42 finally:
  43. 43 con.close()
  44. 44 
  45. 45 if not rows:
  46. 46 print(f"cookie store exists ({os.path.getsize(STORE)} bytes) but holds "
  47. 47 f"no cookies.")
  48. 48 print("Nothing set a cookie while loading the site.")
  49. 49 return 0
  50. 50 
  51. 51 print(f"{len(rows)} cookie(s) present:")
  52. 52 for host, name, path, secure, httponly, has_exp, persistent in rows:
  53. 53 flags = []
  54. 54 if secure:
  55. 55 flags.append("secure")
  56. 56 if httponly:
  57. 57 flags.append("httpOnly")
  58. 58 flags.append("persistent" if persistent else "session")
  59. 59 print(f" {host:<24} {name:<24} {path:<10} {', '.join(flags)}")
  60. 60 
  61. 61 print()
  62. 62 print("The footer says 'no cookies'. That is now false, or needs qualifying.")
  63. 63 return 1
  64. 64 
  65. 65 
  66. 66if __name__ == "__main__":
  67. 67 sys.exit(main())